[Question] In W8-1 and W2012 R2 manifests are packed. How to extract them to XMLtext?

Discussion in 'Windows 8' started by moderate, Sep 5, 2013.

  1. NaiveUser

    NaiveUser MDL Senior Member

    Apr 14, 2011
    419
    523
    10
    Alright, keep on ! you are THAT close ;)
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  2. Mr Jinje

    Mr Jinje MDL Expert

    Aug 19, 2009
    1,769
    1,106
    60
    #22 Mr Jinje, Sep 23, 2013
    Last edited by a moderator: Apr 20, 2017
  3. SuperBubble

    SuperBubble MDL Member

    Nov 18, 2011
    150
    296
    10
    #23 SuperBubble, Sep 23, 2013
    Last edited by a moderator: Apr 20, 2017
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  4. Mr Jinje

    Mr Jinje MDL Expert

    Aug 19, 2009
    1,769
    1,106
    60
    Have you seen any mentions of dpx.dll ?
     
  5. murphy78

    murphy78 MDL DISM Enthusiast

    Nov 18, 2012
    7,432
    11,763
    240
    Yer doin Great SuperBubble! We're all behind ya!
     
  6. moderate

    moderate MDL Guru

    Aug 31, 2009
    3,490
    2,495
    120
    :D
    @Murphy78 is behind you, so do not drop the soap. :)
     
  7. SuperBubble

    SuperBubble MDL Member

    Nov 18, 2011
    150
    296
    10
    #27 SuperBubble, Sep 24, 2013
    Last edited: Sep 24, 2013
    Yes, but curiously enough, there were no calls into it... oh, OH! I see where you're going with this! :)

    But I am the soap. :eek:

    Bonus state of play: OK. I can't find an off-the-shelf tool to help me do this. The latest version of OllyDbg promised much (with its support for debugging into child processes), but since it has surprisingly little control over break on DLL load (it's an all-or-nothing affair)... keeping four processes ticking along so their IPC isn't disturbed, while they load around 100 DLLs between them, is impossible with my slow, fat fingers.
    :throw:

    So, I'm writing what amounts to a damned rootkit to trap all DLL calls, in all child processes. This will take days. :(

    I've not admitted defeat yet. I'm like a dog with a bone, and I won't give up until I've tasted the delicious marrow of MSDELTA.DLL.

    :matrix:
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  8. SuperBubble

    SuperBubble MDL Member

    Nov 18, 2011
    150
    296
    10
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  9. moderate

    moderate MDL Guru

    Aug 31, 2009
    3,490
    2,495
    120
    Nice... :))